Malware

What is “Ursu.93629”?

Malware Removal

The Ursu.93629 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.93629 virus can do?

  • Executable code extraction
  • Sniffs keystrokes

How to determine Ursu.93629?


File Info:

crc32: 3B7EDE2D
md5: 8a460b36b890d98884c206a7661a0801
name: 8A460B36B890D98884C206A7661A0801.mlw
sha1: 69ea3d34bb84a0060dcb57dca87130f204f43b42
sha256: c69a24ea036a8b60fe7641f95decfb85d5148988cadbacaae3c6549c05e8d033
sha512: 7423039a07c965cfef1835fd50b66d8b09849d8aefa85c9c5757e9b0ace478ab48da28caf844f713e9017840ab6cfbc3b29fe3c9ad4aa48fefa47086100ab91c
ssdeep: 6144:rkNgFrYqM9M7L4t0T1acWiLs6WIQWXIcmU3vxs+n:rYUYqM9g4yT86WIZB2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Amazing
FileVersion: 1.03.0001
ProductName: TCP/IP PM
ProductVersion: 1.03.0001
FileDescription: TCP/IP Protocol Manager
OriginalFilename: Amazing.exe

Ursu.93629 also known as:

LionicTrojan.Win32.Blocker.4!c
Elasticmalicious (high confidence)
DrWebBACKDOOR.Trojan
ALYacGen:Variant.Ursu.93629
ZillyaTrojan.Blocker.Win32.35882
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/Blocker.c033f49e
K7GWTrojan ( 0000000c1 )
K7AntiVirusTrojan ( 0000000c1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/VB.ORE
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.jlag
BitDefenderGen:Variant.Ursu.93629
NANO-AntivirusTrojan.Win32.Blocker.eigmak
MicroWorld-eScanGen:Variant.Ursu.93629
TencentWin32.Trojan.Blocker.Eaxa
Ad-AwareGen:Variant.Ursu.93629
SophosMal/Generic-S
ComodoMalware@#1fjacduwpgs7z
BitDefenderThetaGen:NN.ZevbaF.34058.wm0@aKpWwWci
VIPREBackdoor.Win32.Retig.de (v)
McAfee-GW-EditionBehavesLike.Win32.BadFile.fm
FireEyeGeneric.mg.8a460b36b890d988
EmsisoftGen:Variant.Ursu.93629 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Blocker.fqb
AviraTR/Spy.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1C3A47A
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojanDropper:Win32/Randrew.A!rfn
ZoneAlarmTrojan-Ransom.Win32.Blocker.jlag
GDataGen:Variant.Ursu.93629
AhnLab-V3Trojan/Win32.Dynamer.C1658793
McAfeeArtemis!8A460B36B890
MAXmalware (ai score=87)
VBA32Trojan.VB.Levelup
PandaTrj/CI.A
RisingTrojan.Injector!1.B459 (CLASSIC)
YandexTrojan.GenAsa!krIplDrLAaI
IkarusTrojan-Dropper.Delf
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.ORE!worm
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgAASRAA

How to remove Ursu.93629?

Ursu.93629 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment